Bug #81216 [Opn->Csd]: Nullsafe operator leaks dynamic property name
| From: | git@php.net | Date: | Sat, 04 Dec 2021 15:05:27 +0000 |
| Subject: | Bug #81216 [Opn->Csd]: Nullsafe operator leaks dynamic property name | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-238165@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81216&edit=1
ID: 81216
Updated by: git@php.net
Reported by: nikic@php.net
Summary: Nullsafe operator leaks dynamic property name
-Status: Open
+Status: Closed
Type: Bug
Package: Scripting Engine problem
PHP Version: 8.0.8
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of dstogov
Revision: https://github.com/php/php-src/commit/307e476e86e19135976ba7e686558de68dbb9b29
Log: Fixed bug #81216 (Nullsafe operator leaks dynamic property name)
Previous Comments:
------------------------------------------------------------------------
[2021-07-02 08:26:07] nikic@php.net
Related To: Bug #81190
------------------------------------------------------------------------
[2021-07-01 14:42:34] nikic@php.net
Description:
------------
Split off from bug #81190:
<?php
$str = "foo";
null?->{$str . "bar"};
leaks the property name. The opcodes look like this:
0000 ASSIGN CV0($str) string("foo")
0001 T2 = CONCAT CV0($str) string("bar")
0002 T3 = JMP_NULL null 0004
0003 T3 = FETCH_OBJ_R null T2
0004 FREE T3
0005 RETURN int(1)
Note that the CONCAT happens before the JMP_NULL. This is JMP_NULL is part of the delayed opline
stack.
Possibly we could get away with not using delayed oplines with nullsafe, because nullsafe cannot be
used in write context, so not delaying should be safe. It will result in different evaluation order
than non-nullsafe properties though.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81216&edit=1